Globalscape Cuteftp vulnerabilities

7 known vulnerabilities affecting globalscape/cuteftp.

Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2024-1190MEDIUMCVSS 5.5v9.3.0.32024-02-02
CVE-2024-1190 [MEDIUM] CWE-404 CVE-2024-1190: A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of thi
nvd
CVE-2009-3483CRITICALCVSS 9.3v8.3.3v8.3.3.00542009-09-30
CVE-2009-3483 [CRITICAL] CWE-119 CVE-2009-3483: Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a site list containing an entry with a long label.
nvd
CVE-2008-2779CRITICALCVSS 9.3v8.2.02008-06-19
CVE-2008-2779 [CRITICAL] CVE-2008-2779: Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP P Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a
nvd
CVE-2004-1136MEDIUMCVSS 5.0v6.02005-01-10
CVE-2004-1136 [MEDIUM] CVE-2004-1136: Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.
nvd
CVE-2003-1260HIGHCVSS 7.6PoCv5.02003-12-31
CVE-2003-1260 [HIGH] CVE-2003-1260: Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
nvd
CVE-2003-1261LOWCVSS 2.1v5.0v5.0.12003-12-31
CVE-2003-1261 [LOW] CVE-2003-1261: Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.
nvd
CVE-2000-0084MEDIUMCVSS 5.0≤ 2.x2000-01-06
CVE-2000-0084 [MEDIUM] CVE-2000-0084: CuteFTP uses weak encryption to store password information in its tree.dat file. CuteFTP uses weak encryption to store password information in its tree.dat file.
nvd